# Two credentials, deliberately. The runtime role can read and write rows; the # migration role owns the schema. A service that can ALTER its own tables at # runtime turns any code defect into a schema defect. apiVersion: external-secrets.io/v1 kind: ClusterSecretStore metadata: name: openbao-canned-prompts-database labels: app.kubernetes.io/name: canned-prompts railiance-platform/component: external-secrets spec: conditions: - namespaces: - canned-prompts provider: vault: server: http://openbao.openbao.svc:8200 path: database version: v1 auth: tokenSecretRef: name: openbao-canned-prompts-eso-token namespace: external-secrets key: token --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: canned-prompts-postgres-runtime namespace: canned-prompts spec: refreshInterval: 5m secretStoreRef: kind: ClusterSecretStore name: openbao-canned-prompts-database target: name: canned-prompts-postgres-runtime creationPolicy: Owner deletionPolicy: Retain template: engineVersion: v2 data: url: >- postgresql+psycopg://{{ .username | urlquery }}:{{ .password | urlquery }}@platform-pg-2-rw.databases.svc.cluster.local:5432/canned_prompts?sslmode=require dataFrom: - extract: key: creds/canned-prompts-runtime --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: canned-prompts-postgres-migration namespace: canned-prompts spec: refreshInterval: 5m secretStoreRef: kind: ClusterSecretStore name: openbao-canned-prompts-database target: name: canned-prompts-postgres-migration creationPolicy: Owner deletionPolicy: Retain template: engineVersion: v2 data: url: >- postgresql+psycopg://{{ .username | urlquery }}:{{ .password | urlquery }}@platform-pg-2-rw.databases.svc.cluster.local:5432/canned_prompts?sslmode=require dataFrom: - extract: key: creds/canned-prompts-migration --- # The publish token is deliberately NOT declared as an ExternalSecret. # # rapp-postgres confirmed on 2026-09-08 that `creds/canned-prompts-publish` # does not exist and is not being created, at our request. An ExternalSecret # pointing at it would sit permanently unresolved — indistinguishable from a # broken deployment, and an invitation for the next operator to "fix" it by # minting a credential nobody decided to issue. # # Without the secret the service runs READ-ONLY, which is the intended posture # until per-publisher identity exists upstream (RCP-WP-0002-T05). The runtime # Deployment mounts the secret `optional: true`, so it starts cleanly without it # and picks the token up if one is ever added. # # To enable publishing later: have rapp-postgres issue # `creds/canned-prompts-publish`, add the ExternalSecret here, and revisit the # NetworkPolicy ingress rule, which currently admits any namespace.